CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows
Cli ยท 2026-09-09
Actions
Technical Details
| Affected Versions | 1.0.0 through 1.0.212 (Kiro IDE), prior to v2.10.0 (Kiro CLI) |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18656, CVE-2026-18657 |
| Migration Required | Yes |
| Cost Impact | Neutral |
What This Means
For DevOps Teams
Update Kiro IDE to version 1.0.228 and Kiro CLI to version 2.10.0 to address security vulnerabilities CVE-2026-18656 and CVE-2026-18657, ensuring no workarounds are available and immediate action is required to prevent potential code execution from untrusted directories.
For Platform Teams
Deploy the latest versions of Kiro IDE and CLI to incorporate critical security patches for vulnerabilities CVE-2026-18656 and CVE-2026-18657, enhancing platform security and reducing risk of arbitrary code execution from untrusted project directories.
For Executives
Implement immediate upgrade to Kiro IDE version 1.0.228 and Kiro CLI version 2.10.0 to mitigate security vulnerabilities CVE-2026-18656 and CVE-2026-18657, ensuring protection against arbitrary code execution from untrusted project directories on Windows.
Source
Related Cli Updates
- CVE-2026-13769 โ Insecure file permissions in AWS CLI (2026-08-20)
- CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows (2026-08-20)
- CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI (2026-08-20)
- AWS Client VPN now supports CLI, administration controls, and faster connections (2026-08-13)
- CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows (2026-08-04)